CVE-2026-26269Disclosure(vim / vim)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vim vim systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the specialKeys command, affecting Vim builds that enable and use the NetBeans feature. The Stack buffer overflow exists in special_keys() (in src/netbeans.c). The while (*tok) loop writes two bytes per iteration into a 64-byte stack buffer (keybuf) with no bounds check. A malicious NetBeans server can overflow keybuf with a single specialKeys command. The issue has been fixed as of Vim patch v9.1.2148.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vim

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-13); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
vim

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-13: 1Mentions · 2026-02-14: 1Mentions · 2026-02-16: 1Patch / Workaround · 2026-02-13: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-16: 102-1302-1402-16
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-26269: Vim: NetBeans specialKeys Stack Buffer Overflow with Vim <9.1.2148 https://www.openwall.com/lists/oss-security/2026/02/13/2 1. Vim is started with NetBeans integration enabled (e.g. `-nb` option) 2. Vim connects to a NetBeans server 3. The server sends a crafted `specialKeys` command 4. Profit

    Post summary

    CVE-2026-26269 discloses a stack buffer overflow in Vim versions prior to 9.1.2148, caused by a crafted NetBeans specialKeys command.

    01072705
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26269 Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the spe… https://www.cve.org/CVERecord?id=CVE-2026-26269

    Post summary

    CVE-2026-26269 describes a stack buffer overflow in Vim's NetBeans integration that affects versions before 9.1.2148; upgrading to 9.1.2148 resolves the vulnerability.

    00020382
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26269 Stack Buffer Overflow in Vim NetBeans Integration Before 9.1.2148 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26269 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A stack buffer overflow vulnerability (CVE‑2026‑26269) has been disclosed in Vim NetBeans Integration versions prior to 9.1.2148, with technical details provided on Vulmon.

    0000020
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvimvim---

Explore more